Malicious code in v018-axios-cdntest (npm)
-= Per source details. Do not edit below this line.=-
Package impersonates axios v0.18.0 (index.js carries the genuine axios v0.18.0 | (c) 2018 by Matt Zabriskie header and sets window.axios={}, window.__cdn_package='axios@0.18.0') but ships two malicious payloads. (1) index.js appends an IIFE that reads document.cookie and sends it via XMLHttpRequest GET to a hardcoded webhook.site endpoint (https://webhook.site/ef6e7978-f936-4664-b3ff-296a250e1735?c=<cookies>), firing on the page load event so any consumer loading this script via CDN or bundle leaks all accessible cookies to the attacker. (2) Sibling xmr-min.js is an in-browser Monero cryptojacker that constructs a Web Worker from a Blob and uses eval on dynamic JS to mine to wallet 44AFFq5kSiGBoZ4NMDwYtN18obc8AemS33DBLWs3H7otXft3XjrpDtQGv7SqSsaBYBb98uNbr2VBBEt7f2wfn3RVGQBEP3A via pool.supportxmr.com:4444. The package is intended to be loaded through jsdelivr (cdn.jsdelivr.net/npm/v018-axios-cdntest@.../xmr-min.js), so any site embedding it leaks user cookies and burns visitors' CPU. The package's own description self-labels these payloads.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준